CVE-2025-21349

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Feb 11, 2025
CWE ID 287

Summary

CVE-2025-21349 is a Windows Remote Desktop Configuration Service vulnerability that allows an unauthenticated attacker to tamper with the service's settings. By manipulating these settings, an attacker can gain unauthorized access to the system, potentially compromising the security of the entire network. The vulnerability does not require user interaction and can be exploited remotely over the network. Microsoft has released a patch to address this issue, and it is recommended that all Windows systems be updated as soon as possible to protect against potential attacks. This vulnerability can have serious consequences, including data breaches and unauthorized system access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share